← back
CVE-2021-28113medium

CVE-2021-28113

18Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.7epss 22%
exploitation probability
22%top 2% of all CVEs
observed exploitation
nono source reports it
A command injection vulnerability in the cookieDomain and relayDomain parameters of Okta Access Gateway before 2020.9.3 allows attackers (with admin access to the Okta Access Gateway UI) to execute OS commands as a privileged system account.
CVSS:3.1/AC:L/AV:N/A:L/C:H/I:H/PR:H/S:U/UI:N
Affected products
n/a · n/a